Saturday, 26 September 2015

CERT / CC Warns Cookie Vulnerability In Browsers


One problem with the way placed HTTP cookies can ensure that attackers can circumvent HTTPS and can steal private information, warns the CERT Coordination Center (CERT / CC) at Carnegie Mellon University. The problem is in all major browsers.

The problem is that the standard for cookies specifies no mechanism for separation and integrity and browsers do not always authenticate the domain settings of a cookie. An attacker could use this to set a cookie that is used later for an HTTPS connection, instead of the cookie from the website. An attacker can therefore a cookie for example.com locations on the computer that the actual cookie for www.example.com overwrites the victim loads HTTPS content. By another vulnerability used in the server use the cookie to the attacker to obtain private information.

The investigators who have the problem during the last USENIX Security Symposium discussed state that a cookie a so-called "secure flag" may contain, indicating that it has to be sent only over a HTTPS connection. However, there is no corresponding flag that indicates how the cookie is placed. An attacker could via a man-in-the-middle thus inject cookies used on subsequent HTTPS connections. According to the CERT / CC are there attempts to secure cookie management undertaken but all failed due to a lack of a widely implemented standard.

As a solution, the organization that the standard must be adjusted for cookies. In the meantime, the researchers advise websites HSTS (HTTP Strict Transport Security) for a top-level domain to set up and use the "includeSubDomains" option.This partly avoids the possibility of an attacker to place top-level cookies cookies for a subdomain, such as www.domeinnaam.tld override. End users are advised to use the latest browser version. In particular IE users make wise here. Internet Explorer 11 is the only IE version that supports HSTS.

Friday, 25 September 2015

Windows Version For The Internet Of Things Will Bitlocker


A special version of Windows for the Internet of Things (IoT) is intended will have several security measures that are also present in the normal versions. Windows 10 IoT Core is a Windows version without the familiar "Windows shell experience." Developers can develop an app for the operating system immediately to the interface of the device.

Windows 10 IoT Core works currently only on the Raspberry Pi and the second MinnowBoard Max, two mini-computers.The operating system is still in development and Microsoft will soon roll out a new test version. This version will also add multiple security to the system, namely Secure Boot and Bitlocker. Microsoft's Bitlocker encryption software that allows both the complete system and individual files can be encrypted.

Secure Boot is a security standard developed by the computer industry. Once the computer is booted, the firmware verifies the digital signature of each element of the boot software, including firmware, drivers and operating system. If all the signatures are correct will restart the computer and displays the firmware control to the operating system. The test version of Windows 10 IoT Core is via the Windows Insider Program download.

Mozilla: Industry Must Understand Adblock Users Better


In recent weeks on the internet between the supporters and opponents of adblockers a fierce debate erupted, but according to Mozilla, it is important that the industry understands why users use such resources on the web.

The answer here is not entirely clear, according to Mozilla's DENELLE Dixon Thayer. The reasons vary by user and device used. Desktop Users would be more focused on their privacy, and performance, while mobile users want to reduce power and data usage. "As an industry, we need to better understand the wishes of users," said Dixon Thayer. The wishes of users and commercial interests are not mutually exclusive. Rather they are both necessary for a healthy web, according to the Chief Legal Officer of Mozilla.

In addition, especially the collection of usage data plays an important role. According to Dixon-Thayer the collection of data is not inherently detrimental. It can also provide all kinds of benefits. However, it is important that users know this and keep control of the data collected. Otherwise, the confidence in the entire system can be lost, which is also at the expense of the proper parties.

Tracking Protection

Mozilla now wants to determine the cause of the problem which has arisen not only by research but also by developing features and products that provide a better balance and increase confidence in the web. In order to find this balance is also required to the input from users. Therefore, users are asked in the latest beta version of Firefox Private Browsing with Tracking Protection test. Through this feature, users have more control over the data collection.

"As an industry, we need to see which places the user in the product vision instead of the user as a goal to be achieved. It is the only way to respect user choices and the best, most trusted and valuable experience offer, "concludes Dixon Thayer.

Lenovo Again Accused Of Installing Dubious Software


Computer manufacturer Lenovo is again accused of installing dubious software on laptops. Previously, the company came under fire because the Superfish spyware bundled with laptops. Later it turned out that on some models a BIOS rootkit was installed to install the software on their own computers, even though Windows is installed from a clean DVD.

This time enables IT expert Michael Horowitz Lenovo tracking software to install so-called refurbished laptops. Horowitz had two such laptops purchased directly from IBM. The computers were provided with a clean installation of Windows 7 Professional. When analyzing the software on the computer expert saw that the program "Lenovo Customer Feedback Program 64" was performed daily.

According to the description of the program will send the data every day to Lenovo. In the configuration of the software he found a DLL file named Omniture, a company that deals with web analytics and online marketing. "While there appear no additional ads in the ThinkPads, there is something to monitor and track," said Horowitz. "On the one hand, it is surprising because the machines were refurbished and sold by IBM. On the other hand, it is in view of the past of Lenovo not at all surprising."

Lenovo has made ​​a separate page put on the software online. In it, the computer giant announced that Lenovo systems include programs that can communicate with servers on the Internet. It is non-personal and non-identifying information about using the Lenovo software are sent to the company. To avoid this, users with administrative privileges, the scheduled tasks of the Lenovo Customer Feedback Program off.

Apple Publishes List Of Top 25 Infected Apps


Apple has as indicated previously published the list of the 25 infected apps were downloaded the most. The apps infected with malware XcodeGhost, which can send information about the device and apps. According to Apple the malware is not in a position to steal personal information.

We deliberately for a Top 25 chosen because in addition to these 25 applications, the number of affected users is very small. Users who have downloaded an infected app are advised to update the app, which addresses the issue. If the app is no longer available in the App Store, the update will appear soon. In the Top 25 apps are of WeChat, DiDi Taxi, Railroad 12 306, China Unicom, Baidu music, Himalay FM and various games. The apps have been downloaded by millions of people, mainly in China. Furthermore, Apple users will also be separate warn.

EBay Phishing Site Hosted By EBay Itself



EBay users have long been the target of phishing attacks and phishing sites, but researchers have now discovered an eBay phishing site that was hosted on the infrastructure of the auction site itself. The phishing site is offered from the domain ebaydesc.com, which is normally used to host the descriptions of goods offered on eBay.


These descriptions are then displayed via an iframe on the eBay website. Instead of a definition criminals have now created a phishing page that asks for the credentials German eBay users. After users enter their data being sent to the real eBay page, which states that the username or password was invalid.

Meanwhile, the entered credentials sent to a server with a Russian IP address. According to Internet company Netcraft that the phishing page offers discovered eBay by allowing HTML and scripts in the making of descriptions, crooks many opportunities to perform phishing attacks.

Cisco Launches Scanner For Finding Hacked Routers


Cisco has a scanner launched enabling organizations hacked routers can be found on their network where the firmware is updated. Attackers appear to hack through stolen passwords or physical access Cisco routers and install a custom operating system.

This custom operating system is called the SYNFUL Knock-malware. Through the malware continue to keep the attackers access to the corporate network, even resetting the router. Cisco recently conducted a scan on the internet and discovered 199 IP addresses that were infected with the SYNFUL Knock-malware. Now, Cisco has developed a tool that allows customers hacked routers can find on their own network. It is in this case only routers that are infected with the SYNFUL Knock-malware.

The tool does come with a manual. The rotation of the tool via network address translation (NAT) can affect the accuracy of the tool and make sure the tool hacked routers can not detect. Cisco advises to carry out the tool from a network location where there is no NAT between the scanning system and the routers.

Thursday, 24 September 2015

5.6 Million Fingerprints With US Government Stolen



At the hack of US government agency OPM fingerprints from 5.6 million people have been stolen and not 1.1 million, as previously indicated. This is shown by research from the Office of Personnel Management (OPM) and the US Department of Defense.

Public authority, which is responsible for screening officers, was twice hacked. At the first break proved the data of 4.2 million civil servants to be captured. During the investigation into this burglary second burglary was discovered, with much more data were captured. In addition, it was very sensitive data that officials had to fill in the screening forms, such as mental health problems, drug and alcohol use, arrests by police, bankruptcies and user names, passwords, and in some cases fingerprints. In July, it became clear that in this second break-in, the data of 21.5 million Americans have been stolen.

Abuse data

According to experts, the potential for abuse of the stolen fingerprint data limited. This could be in the future, as technology continues to evolve, change. That's why the FBI will, the Department of Homeland Security, the Ministry of Justice and members of the intelligence community launch an investigation to see how this fingerprint data now and in the future can be exploited by enemies.

The parties will also work on ways to prevent such abuse. If it turns out that it is possible to abuse the fingerprint data in the future, the US government will separate the people affected here warn. All affected individuals will be alerted by the OPM on the incident. In addition, all victims eligible for credit monitoring. Something the US government $ 133 million will cost.

Proton Mail Supports Encrypted Emails From Facebook


The free encrypted email service Proton Mail has a new feature added allowing users now receive encrypted emails from Facebook that are automatically decrypted. To make this possible, PGP encrypted emails from Facebook supported. The social networking site decided in June to send encrypted e-mail notifications support.

Facebook users can add their OpenPGP public key to their profile. This key is then used by Facebook for encrypting the email notifications that are sent to the email address of the user. Facebook has chosen to implement the e-mail encryption for GNU Privacy Guard (GPG), the popular and free implementation of the OpenPGP standard.

Ease of Use

Proton Mail claims to be the first e-mail service that supports the PGP-encrypted e-mails from Facebook now "seamless".This means that PGP-encrypted messages from Facebook automatically open in Proton Mail. Previously internet users had to use PGP in Facebook install the PGP software, keys generate and use different plug-ins. Proton Mail users now only need to key in their public Facebook import. If it is the developers will automate this process in the future.

"If we really want a more private and secure Internet is crucial to work together and we congratulate Facebook for the use of open standards," according to the developers of Proton Mail. "We are pleased that major players such as Facebook support these efforts and as more companies will join in the movement to improve online privacy not stop." Proton Mail was developed with the help of scientists from Harvard, the Massachusetts Institute of Technology and the European research lab CERN.

Google: Anti-Virus Software, Kaspersky Still Leak


The anti-virus software of the Russian anti-virus firm Kaspersky Lab still contains multiple vulnerabilities, says Google researcher Tavis Ormandy. Recently released the virus fighter that's been a big leak could poem was found by Ormandy and the system could allow an attacker to take complete without users here had to do something.

The researcher Google has much more major vulnerabilities found in the anti-virus software, so Ormandy late in an analysis of the leak know that are already patched. The analysis was made ​​on the Project Zero blog from Google. Project Zero is a team consisting of Google hackers and researchers looking for vulnerabilities in popular software. This included the anti-virus software from Kaspersky scrutinized.

Not patched

"Many of the bug reports I submitted are still not patched, but Kaspersky has made enough progress that I can talk about some of the problems," as the researcher says. Ormandy had found dozens of bugs in the anti-virus software and reported. The research shows that some of the most dangerous leaks were very easy to abuse. The researcher is pleased that Kaspersky Lab here for additional security rolls out. The impact of a vulnerability will increase in anti-virus software because the virus often file system and network traffic intercepted.

Visiting a website or receive an e-mail is enough to be attacked. It is then not even be necessary to open the e-mail, since the input / output of the reception of the e-mail is sufficient to cause the vulnerability. Besides the discovered vulnerabilities Ormandy also found several major design flaws in other parts of the anti-virus software. These other vulnerabilities to attack his distance. As the updates previously been deferred, he will discuss these issues later.

Security software harmful?

According to Ormandy, there are strong indications that there is an active trade in exploits for antivirus software exists."Research shows that a readily accessible attack surface that exposure to targeted attacks increased enormously," says the researcher. Therefore, he believes that security software developers the strictest security guidelines when developing their software must implement in order to reduce problems caused by the software. Something that fail anti-virus companies. In the past Ormandy has major problems in the software of anti-virus company Sophos and ESET found.

The researcher concludes with a warning and request for anti-virus companies. They would parts of their software does not have to run with system privileges. "Do not wait for the network worm that it has provided in your software, or targeted attacks against your users. Add even today the development of a sandbox to your development plan." Regarding the outstanding vulnerabilities in the software of Kaspersky Ormandy says that the anti-virus company responds very quickly and that a number of critical vulnerabilities in the coming weeks will be patched.

Apple Will Host Xcode In China to Prevent Malware


To new malware in the App Store has Apple decided to prevent the development program Xcode to host locally in China. That Apple chief executive Phil Schiller against the Chinese website Sina.com announced. Last week showed that infected apps in the App Store had ended.

The apps were infected with the XcodeGhost malware. Several Chinese Xcode developers had downloaded from an unofficial website. Xcode is Apple's official tool for developing apps for iOS or OS X. The version that the developers had downloaded were infected with malware, which also became infected by their developed apps. These apps were then placed in the App Store, where Apple controls the malware did not notice.

Download

For Chinese developers may take a very long time to download the 3GB large Xcode. "In the US there is only 25 minutes to download, in China, it may take three times longer," said Schiller. That is also a reason that Chinese developers are trying to download software through unofficial channels. Apple recommends that developers use Xcode and other development software, only download via the official website.

To make this easier for Chinese developers has now decided to host the development programs locally, so they can be downloaded quickly. Regarding XcodeGhost malware according to Schiller, there are no indications that the infected apps user data forwarded.

American 'Funda' Spread Malware Via Infected Ads


Cyber criminals are again managed to place infected ads on a very popular website with tens of millions of visitors who attempted to install malware. It is Realtor.com, the US counterpart of Funda which all kinds of real estate is offered.

The website is according to market researcher Alexa at the 101st place of most visited websites in the United States and a 485ste place worldwide. It is estimated that Realtor.com monthly 28 million visitors. The attackers previously infected ads on the English website of eBay, Drudge Report and other major websites were seated according to anti-malware company Malwarebytes also behind this attack. Through advertising network Adspirit.net the affected ads were posted on the website.

The ads sent visitors without being noticed this through to a website with the Angler-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer to install malware. For whatever it's malware was not disclosed. After being informed, the publisher of Realtor.com and Adspirit off the ads. Internet users whose software was up-to-date were no known risk. Yesterday it became known that criminals a week infected ads on Forbes.com have shown.